Technical Controls
The Technical Controls Evaluations generally require the most time depending on the complexity of the Systems being assessed, and typically cover (but are not limited to) the following elements:
Infrastructure Design,
Network Surveying & Penetration Testing,
Network and Communications Security,
Logical Access Controls,
Operating Systems Security,
Malicious Software Controls,
Database Design and Configuration,
Cryptographic Controls,
System Monitoring,
Reporting and Logging, and
System Development Controls.
|